Segmented Data Access Control via Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems that manage data access based on security rules often permit applications to access all elements of a data unit, leading to potential misuse or misappropriation of sensitive information and inefficient resource utilization due to exposure of obsolete data.

Innovation Solution

A system that uses a machine learning model to identify content segments within data units, generates electronic digital certificates for each segment, and stores them on a distributed ledger, creating smart contracts to manage access, allowing only qualified applications to access specific segments while preventing access to sensitive or obsolete data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are permitted to access all elements of a data unit based on security rules, then access control is simplified, but sensitive information may be misused or misappropriated and computing resources are wasted exposing obsolete data

Engineering Contradiction:
Improveaccess control simplicityVSAvoiddata misuse and resource waste
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides data units into discrete, individually accessible elements or segments. Each element can be independently accessed by applications that meet specific security criteria, rather than accessing the entire data unit. This segmentation allows fine-grained access control that prevents misuse of sensitive information while maintaining simplicity through automated enforcement mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control mechanism that sits between data units and applications. This intermediary evaluates application credentials against security rules and selectively grants access to specific elements within data units, mediating the access process to prevent both data misuse and resource waste while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system processes and manages individual content segments with digital certificates and smart contracts, then data security and access control precision are improved, but system complexity increases

Engineering Contradiction:
Improvedata access securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically generates digital certificates for content segments and enforces access control through smart contracts without requiring manual intervention. Applications automatically present credentials and receive authorized access to permitted elements, reducing the need for complex manual access management while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical access control systems with automated digital mechanisms including cryptographic digital certificates and blockchain-based smart contracts. These automated mechanisms handle security evaluations and access decisions algorithmically, reducing manual complexity while enhancing reliability and precision in access control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240089247A1Systems and methods for extracting discrete data from a data unit and managing access thereto using electronic digital certificates
Publication Date: 2024.03.14 BANK OF AMERICA CORP
  • US20240089247A1 patent drawing
  • US20240089247A1 patent drawing
  • US20240089247A1 patent drawing

AI summary

Systems, computer program products, and methods are described herein for extracting discrete data from a data unit and managing access thereto using electronic digital certificates. The present invention may be configured to receive data units including content, identify discrete data for each data unit, and determine, for each discrete data, qualifications permitting access to the discrete data. The present invention may be configured to generate electronic digital certificates associated with the discrete data and store the electronic digital certificates on a distributed ledger. The present invention may be configured to generate, on the distributed ledger, smart contracts for managing access to the electronic digital certificates by generating smart contracts permitting access to the electronic digital certificates based on the qualifications. The present invention may be configured to automatically permit and/or prevent, using the smart contracts and based on the distributed ledger, access by applications to discrete data.